RSS Amplifier

A Bridge to AI · Jul 15, 2026

The Governance Vacuum Has New Landlords

0
Sign in to vote or save

Dee McCrorey · A Bridge to AI

A wide-format abstract conceptual illustration of a vast, darkened data center / server infrastructure viewed from a low angle — rows of illuminated server racks receding into the distance, each glowing with cool blue-white light.
Image created using Ideogram.ai

The AI Inflection Point (TAIIP) | 2,721 | Reading time: ~12 minutes

In April, this series named a governance vacuum. The gray-zone mismatch of March had created an opening, and the question I asked was “Who’s going to move?”

It turned out to have a faster, more consequential answer than most enterprise leaders anticipated.

This is what filling a vacuum looks like when it happens at infrastructure speed.

Between March and June 2026, five vendors made announcements that, taken individually, sound like product releases. Taken together, they describe something structurally different: a race to own the governance layer of enterprise AI before anyone else defines what that layer should be.

Palo Alto Networks is making the security-layer version of the same argument. Prisma AIRS 3.0, launched in March 2026, positioned itself as the platform for securing the entire agentic AI lifecycle — from design to runtime. The April acquisition of Koi defined a new category: Agentic Endpoint Security. The May acquisition of Portkey established an AI Gateway as the control plane for monitoring, routing, and securing every AI transaction across the enterprise. And Idira, launched in May, extended identity governance to every human, machine, and agentic identity simultaneously. PANW’s framing is precise: agents are “highly privileged insiders” operating at scale, and the governance layer that matters is the security and identity layer.

Note: What makes PANW’s position notable is what a Futurum analysis1 said plainly about its own platform’s limits: Palo Alto can detect anomalous agent behavior, but it cannot define acceptable agent behavior on behalf of the enterprise. Futurum was direct about where that gap sits: with the CIO and CISO. It’s the most honest articulation of the substitution limit any of these vendors has offered, and it comes from their own analyst coverage.

ServiceNow, at Knowledge 2026 in May, expanded AI Control Tower from an optional governance add-on into a comprehensive governance engine bundled into every subscription tier, effective April 9, 2026. Every ServiceNow customer now has governance infrastructure whether they configured it or not. ServiceNow CEO Bill McDermott framed it directly: the company is positioning itself as “the AI agent of agents” — the governance layer for the enterprise, regardless of where AI agents are built, deployed, or operating.

Microsoft launched Agent 365 on May 1 — a $15/user/month control plane for AI agents operating across Microsoft and third-party ecosystems. Futurum’s analysis called the signal plainly: “Microsoft’s intent to own the governance layer for enterprise agentic AI.” The platform extends identity, endpoint, and network controls to agents regardless of where they originate.

Cisco, at Cisco Live in June, unveiled Cloud Control — a unified platform consolidating networking, security, observability, and collaboration management into a single operational environment for both human administrators and AI agents. The platform is the foundation for Cisco’s AgenticOps model. Its marketing language is precise: “humans retain control.” Its architecture is equally precise: agents resolve incidents, manage infrastructure lifecycles, and make operational decisions at machine speed, with human oversight built into the platform’s own framework.

HPE, at Discover 2026 in June, announced GreenLake Intelligence — an agentic AI framework built around the $14 billion Juniper acquisition, with a centralized agent registry, orchestration capabilities, and policy enforcement across infrastructure. HPE’s framing: the network is the governance layer. The Juniper acquisition was the clearest signal yet of why they bought it.

Five vendors. Five control-plane positions. One argument, made from five different infrastructure layers: governance should live where we operate, and we are the infrastructure.

What’s missing from all five: the independent, buyer-defined governance layer that would allow an organization to evaluate whether the vendor’s governance architecture actually reflects their accountability requirements — before the architecture is operational.

There’s a second thing missing, and this month a vendor CEO named it himself. In a July 2026 post, Microsoft’s Satya Nadella described what he calls the “reverse information paradox”2 — the idea that companies using AI systems pay twice: once in fees, and again in the proprietary operational knowledge absorbed into the provider’s learning loop with every prompt and correction. It’s a notable admission from inside the control-plane race: institutional knowledge is turning out to be as contested as governance itself.

Here’s what makes this structurally different from a competitive product cycle.

In a normal competitive market, buyers evaluate competing products, select the one that best fits their requirements, and implement it within their existing governance framework. The governance framework predates the product. The product operates within it.

What’s happening now inverts that relationship. The governance framework is the product. Selecting a vendor now means adopting that vendor’s governance architecture as the operating model — a shift few buyers have named as a selection criterion.

The distinction matters because of timing. As my TCP essay showed this month, AI agents are entering enterprise environments through multiple pathways — contract updates, renewals, platform expansions — routed to reviewers who evaluate scope and relationship fit, not operational downstream impact.

The agent is operational before the governance question is formally raised. And by the time it is raised — in a sustaining review, at renewal, in a board-level risk conversation — the vendor’s control-plane architecture has already answered it.

You didn’t choose their governance model. You inherited it. The last moment you could have negotiated something different passed quietly, and the process wasn’t designed to surface that question.

Anthropic’s 2026 State of AI Agents report3 puts the deployment reality plainly: 57% of organizations now deploy AI agents for multi-stage workflows, and enterprise agent deployments rose 466.7% year-over-year — the fastest single-year expansion on record. Eighty percent (80%) of organizations report those investments are already delivering measurable economic returns. Yet only 21% have a mature governance model for autonomous agents. That means 79% of organizations actively expanding agentic deployments are doing so without adequate controls in place. The gap between those numbers is a sequencing problem: agents are arriving faster than governance frameworks can be built, and the vendors are filling the space between them.

The vendors aren’t defeating governance. That’s an easy argument to make — and easy to dismiss. The more precise argument, and the one that’s harder to see clearly, is that they’re substituting for it.

The substitution looks like a feature because it solves a real problem. Enterprises genuinely don’t have the internal capacity to govern agentic AI systems at the speed those systems operate.

The governance lag is structural — governance frameworks are built by humans, at human speed, for systems that operate at machine speed. The gap was always going to exist. The question was always who would fill it.

ServiceNow’s answer: governance lives at the workflow execution layer, built on two decades of enterprise operational data and 100 billion workflow transactions. Cisco’s answer: governance lives at the infrastructure layer, unified across networking, security, and observability. Microsoft’s answer: governance lives at the identity and endpoint layer, extended to agents regardless of origin. HPE’s answer: governance lives at the network layer, because the network touches everything. Palo Alto Networks’ answer: governance lives at the security and identity layer, because you can’t govern what you can’t see and agents are the new privileged insiders.

Five answers. Five technically coherent positions. Each one also requires buying that vendor’s definition of what governance means, at the layer where they operate, using the accountability framework they designed.

What’s missing from all five: the independent, buyer-defined governance layer that would allow an organization to evaluate whether the vendor’s governance architecture actually reflects their accountability requirements — before the architecture is operational.

There is a second mechanism accelerating this substitution that TCP noted in passing and TAIIP should name directly: the role of major consultancies as the human channel through which vendor control-plane platforms reach enterprise buyers.

A consultancy with existing strategic relationships to both a major infrastructure vendor and a mid-tier enterprise buyer is not simply advising on technology selection. They are intermediaries in a transaction where their incentive structure is aligned with the vendors they certify, implement, and earn margin from — an incentive structure separate from the buyer’s independent governance requirements.

The pathways through which AI agents enter existing vendor relationships are also the pathways through which a consultancy can move a governance platform into an existing engagement without triggering the deeper review that a new contract would require.

The incentive to close, to count the win, and to move an established vendor’s governance platform into an established client relationship operates independently of whether that client’s review process was equipped to evaluate what they were agreeing to.

The conflict of interest is architectural. And it compounds the back door problem: instead of one party with institutional knowledge of a buyer’s internal workflows, the buyer now faces two — the strategic vendor or alliance partner and the consultancy that bridges them.

The vendor-direct version of this dynamic is now emerging as something more immediate.

  • Microsoft has committed $2.5 billion to deploy 6,000 Forward Deployed Engineers (FDEs) through its Frontier Company initiative, embedding engineers directly inside client organizations to build production-grade AI systems alongside internal teams.

  • AWS has launched its own Forward Deployed Engineering segment with a $1 billion commitment. Palantir pioneered the model; OpenAI launched a standalone consultancy doing the same in May 2026.

The ITPro analysis4 puts the strategic intent plainly: FDEs “sit inside the client, where they can drop barriers, cut through red tape, and get in front of decision-makers quickly”, and are increasingly considered “a commercial weapon by cloud providers to secure long-term relationships and spend.”

That’s the amendment back door with an engineering team attached. The FDE enters through a services engagement, builds institutional knowledge of the buyer’s workflows, stakeholders, and decision-making architecture and leaves behind a system that is now load-bearing, deeply integrated, and most efficiently extended by the vendor who built it. The governance question doesn’t disappear when the FDE leaves. It hardens into the architecture they deployed.

If you’ve been reading this series since January, you’ve watched this moment arrive one essay at a time. Here’s the sequence it took to get here:


July’s answer: the vacuum didn’t wait. It was filled at infrastructure speed, by vendors whose competitive logic required them to move — not because anyone planned it this way, but because architecture doesn’t wait for permission, and the governance layer that nobody built independently is now being delivered as a product feature by the companies who build the infrastructure it was supposed to govern.

The substitution is complete enough to look like a solution. The control-plane platforms are real, functional, and solve genuine operational problems. The “humans retain control” language is technically accurate — humans still sign the contracts, still sit in the sustaining review, still attend the board meeting where AI risk gets discussed.

What humans didn’t retain is the moment before the architecture. That moment comes through the back door — a legal amendment, a platform expansion, a bundled update to an existing subscription. That’s what this month’s TCP essay was about.

Boards are asking whether they have an AI governance framework.

The right question is whether their governance framework predates or postdates the vendor’s architecture.

If it predates it — if the organization defined its accountability requirements, its override mechanisms, its data sovereignty terms, its audit rights before signing — then the vendor’s control-plane platform is a tool operating within a buyer-defined framework. That’s governable.

If it postdates it — if the platform was signed, the agents were deployed, the architecture became operational, and then the governance conversation happened — then the vendor’s framework is the governance. The board’s policy document describes what the vendor’s platform already does. That’s ratification, not governance.

A buyer-defined governance framework for agentic AI does exist. Singapore’s Infocomm Media Development Authority (IMDA) unveiled the world’s first Model AI Governance Framework for Agentic AI5 at the World Economic Forum in January 2026, updated to Version 1.5 in May 2026 after incorporating feedback from over 60 organizations. Its four pillars — assess and bound risks upfront, make humans meaningfully accountable, implement technical controls and processes, enable end-user responsibility — map directly onto the accountability gaps the control-plane race is filling by default. The framework is voluntary and nonbinding. Most enterprises haven’t adopted it. The vendors have noticed.

The EU AI Act is beginning to formalize this distinction in binding terms. Deployers — the organizations buying and operating these platforms — carry primary accountability for how high-risk AI systems behave, regardless of what the vendor’s platform claims to provide. “The vendor’s control tower handles that” is not a compliance defense under the Act’s deployer-accountability framework. The accountability lands on the buyer. The governance architecture was supplied by the seller.

That gap — between where accountability lands and where the governance architecture originated — is the structural consequence of the control-plane race.

It’s not visible from the product brochure. It’s visible from the audit, the renegotiation, and the renewal. By then, the architecture has already hardened.

Next month in TAIIP: the leadership layer. The external-hire bet, and what it means when the people being brought in to lead through the AI transition are being selected by boards that don’t yet know what questions they should be asking.

This month in Deep Dive: a Special Mid-Year Deep Dive — available exclusively to paying subscribers. The practitioner’s version of everything named here at altitude, plus a companion Notion workspace with four working tools: an expanded checklist with annotations, an amendment language red flag reference, an agent behavior review meeting template, and a consultancy signal tracker. If you’re navigating any of these conversations right now — an amendment review, a vendor renewal, a leadership conversation where someone just asked a question nobody has a clean answer to — that’s where to start.

This month: the governance vacuum has new landlords. They moved in while the lease was still being drafted.

1

Futurum Group, Prisma AIRS 3.0: Does Palo Alto Own the Agentic AI Security Stack?, March 29, 2026. https://futurumgroup.com/insights/agentic-security/ (Source of “Palo Alto can detect anomalous agent behavior, but it cannot define acceptable agent behavior on behalf of the enterprise” quote)

2

Kobie, Nicole. “A company should be able to use a model without giving up the knowledge that makes it unique”: Microsoft CEO Satya Nadella says enterprises shouldn’t be sharing so much data with AI providers. ITPro, July 14, 2026. (Nadella’s “reverse information paradox” — companies paying twice for AI, in fees and in absorbed proprietary knowledge)

No posts

Read the original on ab2ai.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.